frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Zero Standing Privilege: Marginal Improvement on the Wrong Paradigm

https://gluufederation.medium.com/zero-standing-privilege-marginal-improvement-on-the-wrong-enterprise-security-paradigm-061fde7b84a2
2•mooreds•1h ago

Comments

jiggawatts•1h ago
Except for perhaps at the hyper-scalers where delegated permissions are granted to thousands of support staff, techs, engineers, developers, etc... this kind of fine-grained permission model is a no-go.

It's hard to explain, but it reminds me of the Semantic Web, this totally artificial theoretical construct of how Things Should Be, but... it never worked out like that, and never will. Market forces just don't align with these ivory tower approaches of how things Ought To Be Done.

On the contrary, all too often worse is better, because it scales effortlessly, is faster, and much more importantly: cheaper.

This applies to priviliged identity management (PIM) and its variations.

What I see in most organisations is that the "least trusted" person, the outsourced subcontractor to the contractor, some below-minimum-wage person working out of Chennai is the "Global Admin" (or equivalent) and the CEO, CIO, CTO, and the CISO all have... no special rights. The same as a random secretary.

I see this pattern over and over, organisation after organisation. The exceptions are few and far between, so there must be a reason!

My best guess is that this is because as permissions delegation get finer and finer grained, then the manager delegating the permissions needs better and better knowledge of the technical task to be done in the future to properly and accurately delegate all -- not just some(!) -- of the permissions required to execute that task.

How would you delegate the permissions to fix an "error" (unspecified!) "somewhere" in the tangled network of servers and other equipment?

Remember: No gaps! No missing permissions! This has to be one hundred percent coverage, no edits on the fly, because this troubleshooting could be at 3am on a Sunday after a disaster that could stop the business operating on Monday morning.

No, getting woken up at 3:30am to delegate more permissions is not something most senior managers will accept. Even if they're forced to at gunpoint, what exactly are they going to do? The clock is ticking, the system is down, they don't even know where the problem is! If the +1 permission they just granted is not sufficient, they'll have to grant one more at 4:00am, then 4:30am, then 5:00am and so forth until the business is back up.

This means that with sufficiently fine-grained permissions, eventually the "delegator" has to be 100% involved throughout the entire time complex ad-hoc tasks are performed. This isn't just troubleshooting, it's consultants, it's new deployments, migrations, mergers, splits, role changes, reshuffles, or anything that wasn't 100% perfectly foreseen by the original security delegation architects.

Not to mention that "security architect" is a specialisation with very little overlap with any specific product or business system. The "person in charge" of some database, platform, or product is very unlikely to fully grok delegated ACLs, ZSP, PIM, etc...

This just doesn't scale. Managers overseeing, say, five staff can't be 100% involved in all five staff doing ad-hoc work. Even if they can make this work, what about the next level management, the level from which this manager gets their delegated permissions (which they can further delegate)? Run this up to the level of CIO and with a sufficiently specific access control design you'll have the CIO doing nothing else other than mashing buttons in the some security delegation system such as Active Directory!

It's just soooo much easier to give the lowly tech "Domain Admin" and be done with it.

The alternative with ZSP or whatever is Ivory Tower stuff that only works in "tech organisations" like FAANGs at a huge scale, and nowhere else. You need techs at every layer of management, sufficient scale to justify the effort and not be swamped in overhead.

PS: For comparison, I see a similar effect with ex-FAANG engineers recommending metrics for everything. That's great. I have apps that get 1 real transaction... per month. The other 99.999% of hits in the metric are GoogleBot and random drive-by hackers.

OpenAI, Nvidia Fuel $1T AI Market with Web of Circular Deals

https://www.bloomberg.com/news/features/2025-10-07/openai-s-nvidia-amd-deals-boost-1-trillion-ai-...
1•zerosizedweasle•2m ago•0 comments

Show HN: AI made me this jewel and all I got was AI psychosis

https://fractal-recursive-coherence.vercel.app/
1•kristintynski•7m ago•0 comments

Show HN: Agentic Design Patterns – Python Edition, from the Codex Codebase

https://artvandelay.github.io/codex-agentic-patterns/
1•j_juggernaut•7m ago•0 comments

Serving accelerated FLUX models on Modal

https://docs.thestage.ai/tutorials/source/modal_thestage.html
1•hyp0thetical•8m ago•0 comments

2x Faster Hashes on AWS Graviton: Neon → SVE2

https://ashvardanian.com/posts/aws-graviton-checksums-on-neon-vs-sve/
2•ashvardanian•13m ago•0 comments

They're just trying to earn a buck

https://pluralistic.net/2025/10/07/take-it-easy/#but-take-it
4•laurex•13m ago•0 comments

Marketplace for Automation Workflows

https://www.neura.market/
1•lovereading•15m ago•1 comments

Can Cory Doctorow's Book 'Enshittification' Change the Tech Debate?

https://www.nytimes.com/2025/10/05/books/review/cory-doctorow-enshittification.html
3•coloneltcb•16m ago•2 comments

High-fat diet impairs memory by autophagic-lysosomal dysfunction in Drosophila

https://journals.plos.org/plosgenetics/article?id=10.1371/journal.pgen.1011818
2•PaulHoule•21m ago•1 comments

Not Another Workflow Builder

https://blog.langchain.com/not-another-workflow-builder/
1•clemo_ra•22m ago•0 comments

Qupak: Pattern Matching for Prolog with library(reif)

https://github.com/bakaq/qupak
1•triska•22m ago•0 comments

Princeton Engineering Anomalies Research

https://pearlab.icrl.org/
1•walterbell•23m ago•0 comments

Silicon Valley wants to help me make a superbaby. Should I let it?

https://sfstandard.com/2025/06/01/silicon-valley-wants-to-help-me-make-a-superbaby-should-i-let-it/
2•NoRagrets•26m ago•1 comments

Air traffic controllers working without pay begin to call out sick

https://abcnews.go.com/US/air-traffic-controllers-working-pay-begin-call-sick/story?id=126289491
7•geox•26m ago•1 comments

Building a JavaScript Runtime from Scratch using C

https://devlogs.xyz/blog/building-a-javaScript-runtime
1•redbell•30m ago•0 comments

Python 3.14 Released with Template String Literals, Deferred Annotations, and

https://socket.dev/blog/python-3-14-released
2•feross•31m ago•0 comments

I struggle to find old messages in ChatGPT conversations

https://ai-answer-saver.vercel.app/
1•nemo30s•33m ago•1 comments

InstaVolt is using GPS tracking to catch thieves stealing its EV charging cables

https://electrek.co/2025/10/07/uk-ev-chargers-instavolt-gps-tracking/
2•breve•33m ago•0 comments

West Coast's two monster faults could trigger back-to-back earthquakes

https://www.latimes.com/california/story/2025-10-07/what-could-trigger-a-massive-quake-on-califor...
1•dangle1•34m ago•0 comments

Show HN: Getting AI Models to Wink – The Wink Test

https://www.cinemodels.ai/benchmark?test=wink
2•niwrad•35m ago•1 comments

AI ML Jargon

https://github.com/hemanth/ai-ml-jargon
2•init0•40m ago•0 comments

Gemini Browser

https://gemini.browserbase.com/
1•jonbaer•41m ago•0 comments

Hulu Becomes Global General Entertainment Brand on Disney+ Beginning October 8

https://thewaltdisneycompany.com/hulu-global-brand-disney-plus/
1•ChrisArchitect•45m ago•0 comments

Investing in America 2025

https://blog.google/inside-google/company-announcements/investing-in-america-2025/
21•gmays•48m ago•10 comments

N.J. Attorney General Investigating Uber over Handling of Sexual Assaults

https://www.nytimes.com/2025/10/07/business/uber-nj-attorney-general-sexual-assaults.html
1•vinni2•48m ago•0 comments

RIP Robert Murray-Smith (1963 – 2025) [video]

https://www.youtube.com/watch?v=GhramXiUrY4
2•pierrec•51m ago•0 comments

Brazil's Finance Minister confirms studies on eliminating public transport fares

https://www.reuters.com/world/americas/brazils-finance-minister-confirms-studies-eliminating-publ...
2•CXSHNGCB•51m ago•0 comments

We evaluated Google's new computer use model on real websites

https://www.browserbase.com/blog/evaluating-browser-agents
1•MiguelG719•51m ago•0 comments

What's new in Python 3.14

https://docs.python.org/3/whatsnew/3.14.html
1•hahahacorn•52m ago•0 comments

Agentic workflow integrating any REST API into a graph using GraphOS MCP Tools

https://www.youtube.com/watch?v=MoPYTN4piQc
2•apollo-watson•54m ago•1 comments